Anthropic is opening more of Claude’s advanced cybersecurity capabilities to vetted defenders, expanding access to its strongest models through a revamped Cyber Verification Program designed for security operations, incident response, red teaming and critical-infrastructure testing.
The move matters because Anthropic has historically kept conservative cybersecurity safeguards on its generally available models to reduce the risk that the same tools used to find vulnerabilities could also be used to exploit them. The expanded program attempts to give legitimate security teams more capability while preserving tighter controls for the public.

What Anthropic announced
On 6 October 2026, Anthropic announced an expanded Cyber Verification Program (CVP) that combines the company’s previous CVP with Project Glasswing into a single three-tier access system.
Qualifying participants can receive access to Anthropic’s most capable models, including Claude Opus 5.5, Claude Sonnet 5.5 and Claude Mythos 5.1, with different safeguards depending on the level of cybersecurity work they are authorised to perform.
Anthropic says the aim is to give defenders access to capabilities that would otherwise be blocked by conservative cyber safety classifiers on generally available Claude models.
Official source: Anthropic — Expanding the Cyber Verification Program.
The new three-tier model
Defense Access
The broadest tier is aimed at defensive cybersecurity work. Anthropic says this can include security operations centre tasks, incident response, malware reverse engineering, vulnerability analysis and validation.
Potentially eligible users include company security teams, universities, government bodies, nonprofits, critical-infrastructure operators, smaller security firms, open-source maintainers and experienced individual researchers with a history of responsible vulnerability disclosure.
Anthropic says it expects many legitimate defensive organisations to qualify and aims to respond to applications within several days.
Red Team Access
The second tier adds authorised penetration testing and red-team activity.
This tier is aimed at in-house security teams, government red teams and professional penetration-testing firms that are authorised to test the systems they target.
Anthropic says some safeguards remain. Actions that could cause physical harm or mass disruption — such as deploying ransomware, damaging physical systems or testing certain high-risk safety systems — can still be blocked.
Applications are subject to stronger verification and can take several weeks. The tier is currently available to organisations rather than individual researchers.
Specialized Access
The highest tier is intended for a relatively small group of deeply vetted organisations working on safety-critical systems.
Anthropic cites examples such as power grids, flight operating systems, telecommunications networks, interbank transfer infrastructure and government administrative networks.
According to the company, these organisations receive the fewest cyber blocks because their work can require realistic testing of highly sensitive systems. Anthropic says applicants are reviewed in depth in collaboration with the US government.
Why Anthropic is loosening safeguards for vetted defenders
Cybersecurity is a classic dual-use problem.
A model capable of finding an exploitable software flaw can help a security team patch it — or help an attacker weaponise it. That is why Anthropic’s public Claude models generally apply restrictive cyber safeguards to many advanced tasks.
The company argues that overly broad blocking can also become a defensive disadvantage if legitimate security teams cannot use frontier models for real-world work.
The expanded CVP is Anthropic’s attempt to solve that problem through identity verification, organisational vetting and tier-specific controls instead of offering the same cyber capability to every user.

Anthropic says Claude helped uncover at least 129,000 vulnerabilities
The strongest argument Anthropic gives for expanding the program comes from Project Glasswing.
According to Anthropic, partners using Claude Mythos uncovered at least 129,000 verified software vulnerabilities between April and July 2026.
Anthropic says its own open-source scanning identified an additional 5,500 verified vulnerabilities between April and October 2026, while more than 33,000 of the verified vulnerabilities identified so far were rated critical or high severity.
Those numbers should be interpreted carefully. They are Anthropic’s reported program results, not an independently audited industry-wide count. The company also says its figures are based on reports from only a subset of participating organisations and may significantly understate the total impact.
Reuters separately reported that Anthropic believes the real number of flaws identified through the broader program may be several times higher than the surveyed total.
How capable are the models once safeguards are reduced?
Anthropic also published internal evaluation results using a benchmark called CyScenarioBench, which tests multi-stage cyber operations under realistic constraints.
Without CVP access, Anthropic says every tested task was blocked at the first prompt.
Under Defense Access, 46 of 50 trials were blocked at some point, while four succeeded.
Under Red Team Access, Anthropic says there were no safeguard blocks and Claude Opus 5.5 completed 34 of 50 tasks — roughly the same success rate as the model achieved when no cyber safeguards were applied.
The company says these results support its view that capability can be opened selectively without removing protection for general users.
What this could mean for cybersecurity teams
If the program works as intended, frontier AI models could become more useful across several parts of defensive security.
- Vulnerability discovery: scanning source code and systems for flaws that might take human teams significantly longer to identify.
- Incident response: helping analysts interpret logs, malware behaviour and attack chains during active investigations.
- Reverse engineering: assisting teams analysing malicious software and unfamiliar binaries.
- Red teaming: simulating real attack paths against systems an organisation is authorised to test.
- Critical infrastructure: stress-testing systems where ordinary cyber restrictions could prevent realistic defensive evaluation.
The potential benefit is speed. Security teams often face more alerts, code and vulnerabilities than they can investigate manually. AI systems that can triage, reason across large codebases and automate repetitive analysis could materially change the economics of defence.
The risk: attackers want the same capabilities
The difficult part is that the same improvements also increase the value of frontier models to malicious actors.
Anthropic’s approach therefore depends heavily on verification, monitoring and access controls. Organisations enrolled in the program are generally subject to data-retention requirements so Anthropic can monitor for cyber misuse.
The company says it is also developing Enterprise Frontier Safeguards, intended to combine stronger privacy with robust security controls for eligible organisations.
Why this matters beyond Anthropic
Anthropic is not the only AI company confronting this trade-off. Cybersecurity has become an increasingly important competitive battleground for frontier AI developers.
Google has been giving selected security partners access to advanced Gemini models, while governments are simultaneously becoming more concerned about AI systems being used in attacks against companies and public infrastructure.
Recent incidents have intensified that pressure. South Korean authorities said AI appeared to have been used in cyberattacks targeting major commercial banks, while Australia has been debating mandatory reporting obligations for serious incidents involving AI agents.
The broader policy question is becoming difficult to avoid: should the most capable cyber features of frontier AI models be widely available, or reserved for users who can prove they are legitimate defenders?
A likely model for frontier AI access
Anthropic’s new structure may point toward a broader future for advanced AI services.
Rather than giving every customer exactly the same model capabilities, AI companies may increasingly offer verified access tiers for high-risk domains such as cybersecurity, biological research, critical infrastructure and government systems.
That could allow powerful models to be used where they provide the greatest defensive value while preserving more restrictive settings for anonymous or lightly verified users.
Whether that balance is sufficient will depend on how well verification works, how misuse is detected and how quickly model capabilities continue to advance.
The bottom line
Anthropic is making a deliberate bet: that advanced cyber capability should not simply be switched off because it is dangerous, but should instead be opened selectively to organisations capable of using it responsibly.
The reported Project Glasswing results suggest frontier models can already accelerate vulnerability discovery at meaningful scale. The expanded Cyber Verification Program now attempts to make that capability available to a much wider pool of defenders without giving unrestricted offensive access to everyone.
For cybersecurity teams, the announcement could make Claude substantially more useful. For regulators and AI developers, it is another test of whether powerful dual-use models can be governed through access controls rather than blanket restrictions.
Important disclaimer
This article is provided for general news and informational purposes only. It does not constitute cybersecurity, legal, technical, compliance, risk-management or other professional advice and should not be relied upon as advice tailored to your organisation or circumstances.
Cybersecurity tools and AI capabilities can create significant operational and legal risks. Organisations should obtain independent advice from appropriately qualified cybersecurity, legal, compliance and technical professionals before deploying AI systems for penetration testing, vulnerability research, critical-infrastructure testing or other sensitive security activities.
Figures attributed to Anthropic reflect the company’s reported program results and should not be interpreted as independently audited guarantees of performance. See the NextNews disclaimer for further information.
Disclaimer
NextNews strives for accurate news, but use it with caution—content changes often, external links may be iffy, and technical glitches happen. See the full disclaimer for details.
